# Top

**URL:** https://discuss.elastic.co/top.md?page=31&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 32

---

## [How to split xml arrays?](https://discuss.elastic.co/t/how-to-split-xml-arrays/51944)

<div class="topic-metadata">

**Author:** [@pazarr](https://discuss.elastic.co/u/pazarr)\
**Replies:** 14\
**Last updated:** [October 14, 2016, 8:35am UTC](https://discuss.elastic.co/t/how-to-split-xml-arrays/51944 "2016-10-14T08:35:55Z")

</div>

Hi Folks, I'm pretty new in ELK stack. I'm trying to parse xml and get the all elements from array send to elasticsearch. So I wrote this filter which works fine: filter { xml { source =\> "message" #ta…

---

## [Elasticsearch 2.3 poor performance](https://discuss.elastic.co/t/elasticsearch-2-3-poor-performance/57359)

<div class="topic-metadata">

**Author:** [@Bit](https://discuss.elastic.co/u/Bit)\
**Replies:** 23\
**Last updated:** [August 18, 2016, 2:41pm UTC](https://discuss.elastic.co/t/elasticsearch-2-3-poor-performance/57359 "2016-08-18T14:41:03Z")

</div>

I have ES 1.7.5 cluster with 20 servers. Maximum indexing performance of this cluster is about 6000-7000 docs/sec. Average size of document is about 1.5 Kbytes First (optional :slight\_smile: question what do you think …

---

## [Как правильно сортировать выдачу?](https://discuss.elastic.co/t/topic/35729)

<div class="topic-metadata">

**Author:** [@stanleer](https://discuss.elastic.co/u/stanleer)\
**Replies:** 21\
**Last updated:** [February 11, 2016, 4:38pm UTC](https://discuss.elastic.co/t/topic/35729 "2016-02-11T16:38:11Z")

</div>

Использую прослойку elastica Есть индекс с уличами и номерами домов. Без указания параметров все ищется нормально. $resultSet = $search-\>addIndex($this-\>\_index) -\>addType('street') -\>search($text."\*") ; Ка…

---

## [Logstash command not found error](https://discuss.elastic.co/t/logstash-command-not-found-error/114797)

<div class="topic-metadata">

**Author:** [@alpha\_gamma](https://discuss.elastic.co/u/alpha_gamma)\
**Replies:** 9\
**Last updated:** [January 10, 2018, 11:08am UTC](https://discuss.elastic.co/t/logstash-command-not-found-error/114797 "2018-01-10T11:08:06Z")

</div>

I have ubuntu 16.04 system, I ahve logstash installed in /etc/logstash the command sudo service logstash start works well but the command /bin/logstash -f logstash.conf does work I have one more location /usr/share/…

---

## [How i can integrate weblogic with elastic seach?](https://discuss.elastic.co/t/how-i-can-integrate-weblogic-with-elastic-seach/68272)

<div class="topic-metadata">

**Author:** [@Pratik\_Jain](https://discuss.elastic.co/u/Pratik_Jain)\
**Replies:** 15\
**Last updated:** [December 12, 2016, 10:53am UTC](https://discuss.elastic.co/t/how-i-can-integrate-weblogic-with-elastic-seach/68272 "2016-12-12T10:53:13Z")

</div>

i want to integrate weblogic with elastic search & logstash and i am new to this so how i can do this.

---

## ["hash=event\['field'\].to\_hash" instead "hash = event.to\_hash"](https://discuss.elastic.co/t/hash-event-field-to-hash-instead-hash-event-to-hash/24169)

<div class="topic-metadata">

**Author:** [@Saket\_Kumar](https://discuss.elastic.co/u/Saket_Kumar)\
**Replies:** 15\
**Last updated:** [June 25, 2015, 6:06am UTC](https://discuss.elastic.co/t/hash-event-field-to-hash-instead-hash-event-to-hash/24169 "2015-06-25T06:06:03Z")

</div>

Is it possible... I want to traverse through events against specific field. something like: hash = event\['field1'\].to\_hash hash.each { |event\['field1'\], v| puts event\['field1'\] if v == hash.values.max } Any help?

---

## [How to export \`alerts\` as backup?](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715)

<div class="topic-metadata">

**Author:** [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Replies:** 12\
**Last updated:** [February 6, 2021, 3:58am UTC](https://discuss.elastic.co/t/how-to-export-alerts-as-backup/261715 "2021-02-06T03:58:02Z")

</div>

Hi thanks for the lib! I am trying to monitor my server by using monitoring and alerting. When, for example, CPU is too high or memory is almost full, I want to send an email to myself. Thus I use Kibana Alerting (is it …

---

## [Only speficied fields](https://discuss.elastic.co/t/only-speficied-fields/86788)

<div class="topic-metadata">

**Author:** [@Giuseppe\_Merlo](https://discuss.elastic.co/u/Giuseppe_Merlo)\
**Replies:** 13\
**Last updated:** [May 24, 2017, 7:20am UTC](https://discuss.elastic.co/t/only-speficied-fields/86788 "2017-05-24T07:20:28Z")

</div>

Hi forum! There is a way that make me able to insert into an index only specified fields? Here is an example: I create the Anime index with only name field, this is my Anime.mapping file: { "properties": { …

---

## [Elasticsearch isn't working with host IP](https://discuss.elastic.co/t/elasticsearch-isnt-working-with-host-ip/185969)

<div class="topic-metadata">

**Author:** [@CMonty](https://discuss.elastic.co/u/CMonty)\
**Replies:** 11\
**Last updated:** [June 18, 2019, 12:37am UTC](https://discuss.elastic.co/t/elasticsearch-isnt-working-with-host-ip/185969 "2019-06-18T00:37:06Z")

</div>

I am setting up Elasticsearch but it only seems to work with local host. When I go into elasticsearch.yml I uncomment out only network.host & http.port as the tutorial states. It works when I leave network.host as "loca…

---

## [Invalid index name](https://discuss.elastic.co/t/invalid-index-name/111131)

<div class="topic-metadata">

**Author:** [@Alex\_Davidovich](https://discuss.elastic.co/u/Alex_Davidovich)\
**Replies:** 12\
**Last updated:** [December 16, 2017, 3:55am UTC](https://discuss.elastic.co/t/invalid-index-name/111131 "2017-12-16T03:55:52Z")

</div>

I have a 3 nodes cluster with 1 primary shards on 1 node and 1 replica on each other node. My index has a name and an alias "current". I am bulk inserting into the master only via the alias name "current". That's work…

---

## [Upgrade from 6.4 to 7.2](https://discuss.elastic.co/t/upgrade-from-6-4-to-7-2/188531)

<div class="topic-metadata">

**Author:** [@han1](https://discuss.elastic.co/u/han1)\
**Replies:** 44\
**Last updated:** [July 3, 2019, 6:20pm UTC](https://discuss.elastic.co/t/upgrade-from-6-4-to-7-2/188531 "2019-07-03T18:20:36Z")

</div>

We have just upgraded our deployment from 6 to version 7.2 We have created 7 indices and in Kabana it show all of them having documents. However, when we try to view the documents, only one of the indices shows the doc…

---

## [Memory usage of the machine with ES is continuously increasing](https://discuss.elastic.co/t/memory-usage-of-the-machine-with-es-is-continuously-increasing/23537)

<div class="topic-metadata">

**Author:** [@vangap](https://discuss.elastic.co/u/vangap)\
**Replies:** 15\
**Last updated:** [February 4, 2016, 10:04am UTC](https://discuss.elastic.co/t/memory-usage-of-the-machine-with-es-is-continuously-increasing/23537 "2016-02-04T10:04:46Z")

</div>

ES version 1.5.2 Arch Linux on Amazon EC2 of the available 16 GB, 8 GB is heap (mlocked). Memory consumption is continuously increasing (225 MB per day). Total no of documents is around 800k, 500 MB. cat /proc/memin…

---

## [New cluster best practice - discovery.zen.ping.unicast.hosts:](https://discuss.elastic.co/t/new-cluster-best-practice-discovery-zen-ping-unicast-hosts/186964)

<div class="topic-metadata">

**Author:** [@jamesp220291](https://discuss.elastic.co/u/jamesp220291)\
**Replies:** 9\
**Last updated:** [June 24, 2019, 6:40am UTC](https://discuss.elastic.co/t/new-cluster-best-practice-discovery-zen-ping-unicast-hosts/186964 "2019-06-24T06:40:08Z")

</div>

Hi I am building the below cluster 3x dedicated masters 3x dedicated data nodes 1x coordinator node In the setting - discovery.zen.ping.unicast.hosts: Do I only put the 3x dedicated masters, or shall I put the IP's…

---

## [Logstash not picking the file after placing in the input path](https://discuss.elastic.co/t/logstash-not-picking-the-file-after-placing-in-the-input-path/180703)

<div class="topic-metadata">

**Author:** [@syed\_faheem\_Hussain](https://discuss.elastic.co/u/syed_faheem_Hussain)\
**Replies:** 44\
**Last updated:** [May 21, 2019, 6:50pm UTC](https://discuss.elastic.co/t/logstash-not-picking-the-file-after-placing-in-the-input-path/180703 "2019-05-21T18:50:55Z")

</div>

I have placed the config.properties file with input of the log file path but whenever a new file is put in that location it is not fetching the latest file my conf as below input { file { path =\> "/mnt/storage/logs/\*" …

---

## [Wildcard search with space in the text](https://discuss.elastic.co/t/wildcard-search-with-space-in-the-text/215797)

<div class="topic-metadata">

**Author:** [@jwlee](https://discuss.elastic.co/u/jwlee)\
**Replies:** 10\
**Last updated:** [January 23, 2020, 4:56am UTC](https://discuss.elastic.co/t/wildcard-search-with-space-in-the-text/215797 "2020-01-23T04:56:34Z")

</div>

Wildcard search seems not working if a value contains space. For example, if a value is "hello world" and if you do search hel\* it does not return anything. Below is the query that I used: { "query": { "bool": …

---

## [Json file from filebeat to Logstash and then to elasticsearch](https://discuss.elastic.co/t/json-file-from-filebeat-to-logstash-and-then-to-elasticsearch/108039)

<div class="topic-metadata">

**Author:** [@mussa572](https://discuss.elastic.co/u/mussa572)\
**Replies:** 12\
**Last updated:** [November 29, 2017, 1:57am UTC](https://discuss.elastic.co/t/json-file-from-filebeat-to-logstash-and-then-to-elasticsearch/108039 "2017-11-29T01:57:17Z")

</div>

Hi I am few in setting filbeat, wondering i can get some advise . I am trying to ingested inventory data which is produced following json fileformat . { "\_meta": { "hostvars": { "host1": { "foreman": { "architectu…

---

## [Connection Refused when trying to connect using REST template client from outside](https://discuss.elastic.co/t/connection-refused-when-trying-to-connect-using-rest-template-client-from-outside/185396)

<div class="topic-metadata">

**Author:** [@priyankajn](https://discuss.elastic.co/u/priyankajn)\
**Replies:** 13\
**Last updated:** [June 20, 2019, 1:23pm UTC](https://discuss.elastic.co/t/connection-refused-when-trying-to-connect-using-rest-template-client-from-outside/185396 "2019-06-20T13:23:37Z")

</div>

Hi, I have elastic search cluster of 2 nodes and trying to call the REST API from a spring boot application using a rest client. It's giving me connection refused error every time. It works when I set the network.host: 0…

---

## [What bottleneck am I hitting?!](https://discuss.elastic.co/t/what-bottleneck-am-i-hitting/54860)

<div class="topic-metadata">

**Author:** [@Janet](https://discuss.elastic.co/u/Janet)\
**Replies:** 12\
**Last updated:** [August 4, 2016, 5:30am UTC](https://discuss.elastic.co/t/what-bottleneck-am-i-hitting/54860 "2016-08-04T05:30:34Z")

</div>

This has been driving me batty for a couple of days. I can't get my ELK stack to index above 36k per second, no matter how I try to scale horizontally.. The machines: 3 Master nodes (4 core 14g mem Azure VMs), 2 Cli…

---

## [How to create a watch that email specific field from input index?](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947)

<div class="topic-metadata">

**Author:** [@ruchira](https://discuss.elastic.co/u/ruchira)\
**Replies:** 17\
**Last updated:** [September 9, 2016, 9:22am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947 "2016-09-09T09:22:17Z")

</div>

Hi, I wanna include some filed from index to email body of action how I can do that? curl -XPUT 'http://localhost:9200/\_watcher/watch/log\_error\_watch' -d '{ "trigger" : { "schedule" : { "interval" : "10s" } }, "inp…

---

## [Problem getting autodiscover docker to work with filebeat](https://discuss.elastic.co/t/problem-getting-autodiscover-docker-to-work-with-filebeat/144349)

<div class="topic-metadata">

**Author:** [@sgreszcz](https://discuss.elastic.co/u/sgreszcz)\
**Replies:** 10\
**Last updated:** [August 15, 2018, 12:31pm UTC](https://discuss.elastic.co/t/problem-getting-autodiscover-docker-to-work-with-filebeat/144349 "2018-08-15T12:31:16Z")

</div>

I'm trying to get the filebeat.autodiscover feature working with type:docker. If I put in this default configuration, I don't see anything coming into Elastic/Kibana (although I am getting the system, audit, and other l…

---

## [Use of Split Filter for more than 1 fields, it is possible](https://discuss.elastic.co/t/use-of-split-filter-for-more-than-1-fields-it-is-possible/97687)

<div class="topic-metadata">

**Author:** [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Replies:** 14\
**Last updated:** [August 29, 2017, 7:23am UTC](https://discuss.elastic.co/t/use-of-split-filter-for-more-than-1-fields-it-is-possible/97687 "2017-08-29T07:23:39Z")

</div>

Hi All my output is like this Field1 : A,B,C,D Field2: E,F,G,H Field3: W,X,Y,Z Field4: Q,R,S,T Now i am using split filter in conf file split {field =\> "\[Field1 \]"} split {field =\> "\[Field2\]"} split {field =\> …

---

## [SAML error with ELK Stack](https://discuss.elastic.co/t/saml-error-with-elk-stack/164673)

<div class="topic-metadata">

**Author:** [@vapetri](https://discuss.elastic.co/u/vapetri)\
**Replies:** 50\
**Last updated:** [April 3, 2019, 1:45pm UTC](https://discuss.elastic.co/t/saml-error-with-elk-stack/164673 "2019-04-03T13:45:48Z")

</div>

Hi guys, i am trying to configure Kibana authentication via SAML with oracle IAM stack as an Identity provider. In elasticsearch log we have: org.elasticsearch.ElasticsearchSecurityException: Cannot find any matching…

---

## [Logstash Configuration File Ordering Does Matter](https://discuss.elastic.co/t/logstash-configuration-file-ordering-does-matter/28840)

<div class="topic-metadata">

**Author:** [@Yarden\_Bar](https://discuss.elastic.co/u/Yarden_Bar)\
**Replies:** 12\
**Last updated:** [February 9, 2016, 9:35am UTC](https://discuss.elastic.co/t/logstash-configuration-file-ordering-does-matter/28840 "2016-02-09T09:35:22Z")

</div>

Hi all, I'm running logstash with a couple of -f switches and for some unknown reason, the order of the files does matter: input-filter-output: ~/util/logstash-1.5.4/bin/logstash -f ./conf.d/input-50-email-sending.conf…

---

## [Not able to read Kafka - Avro Schema messages](https://discuss.elastic.co/t/not-able-to-read-kafka-avro-schema-messages/24979)

<div class="topic-metadata">

**Author:** [@karthikr](https://discuss.elastic.co/u/karthikr)\
**Replies:** 15\
**Last updated:** [October 20, 2016, 3:58pm UTC](https://discuss.elastic.co/t/not-able-to-read-kafka-avro-schema-messages/24979 "2016-10-20T15:58:29Z")

</div>

I want to read snappy compressed avro messages stored in kafka into elastic. I am using the Kafka Input Plugin and the Avro Logstash Codec but not able to read the compressed messages. Do note that I am able to read plai…

---

## [Logstash 6 - Multiple Pipelines for One Input](https://discuss.elastic.co/t/logstash-6-multiple-pipelines-for-one-input/107929)

<div class="topic-metadata">

**Author:** [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Replies:** 9\
**Last updated:** [November 18, 2017, 4:35pm UTC](https://discuss.elastic.co/t/logstash-6-multiple-pipelines-for-one-input/107929 "2017-11-18T16:35:20Z")

</div>

Hi all, Currently in Logstash 5.x I have one Input (Beats) about which I get many different kinds of logs. To grok this logs, I have many config files with filter like "if \[type\] == "yxz....." defined. The results i…

---

## [Parsing xml using logstaash xpath](https://discuss.elastic.co/t/parsing-xml-using-logstaash-xpath/119274)

<div class="topic-metadata">

**Author:** [@Karanushah.1992](https://discuss.elastic.co/u/Karanushah.1992)\
**Replies:** 23\
**Last updated:** [February 12, 2018, 6:17pm UTC](https://discuss.elastic.co/t/parsing-xml-using-logstaash-xpath/119274 "2018-02-12T18:17:53Z")

</div>

HI, I am trying to parse an XML file in Logstash. I want to use XPath to do the parsing of documents in XML. So when I run my config file the data loads into elasticsearch but It is not in the way I want to load the dat…

---

## [How to access the value in the logstash metadata](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200)

<div class="topic-metadata">

**Author:** [@bijay](https://discuss.elastic.co/u/bijay)\
**Replies:** 14\
**Last updated:** [November 19, 2018, 3:42pm UTC](https://discuss.elastic.co/t/how-to-access-the-value-in-the-logstash-metadata/157200 "2018-11-19T15:42:40Z")

</div>

Hi, I want to access the value of the dictionary in the metadata dynamically. How can I do that in logstash filter section? e.g. if \[@metadata\]\[key\] == "test" { \<some action\> } Thanks Bijay

---

## [Elastic-search SSL certification error, unable to open kibana](https://discuss.elastic.co/t/elastic-search-ssl-certification-error-unable-to-open-kibana/194340)

<div class="topic-metadata">

**Author:** [@asad\_ali](https://discuss.elastic.co/u/asad_ali)\
**Replies:** 9\
**Last updated:** [August 10, 2019, 11:03am UTC](https://discuss.elastic.co/t/elastic-search-ssl-certification-error-unable-to-open-kibana/194340 "2019-08-10T11:03:36Z")

</div>

I'm unable to open kibana as elastic-search is irresponsive as I made changes to elasticsearch.yml for SSL authentication. On dashboard on webpage i get "Cannot connect to the Elasticsearch cluster". My elasticsearch.y…

---

## [Load balancing ElasticSearch with virtual ip?](https://discuss.elastic.co/t/load-balancing-elasticsearch-with-virtual-ip/12897)

<div class="topic-metadata">

**Author:** [@Tommy\_Albinsson](https://discuss.elastic.co/u/Tommy_Albinsson)\
**Replies:** 16\
**Last updated:** [July 31, 2013, 9:14am UTC](https://discuss.elastic.co/t/load-balancing-elasticsearch-with-virtual-ip/12897 "2013-07-31T09:14:29Z")

</div>

Hi, I am setting up a new environment with ElasticSearch, and the out of the box zen discovery makes it real easy to load balance. But if I want to set up my environment like the following. Three servers runni…

---

## [Logstash Pipeline Configuration & inputs](https://discuss.elastic.co/t/logstash-pipeline-configuration-inputs/158288)

<div class="topic-metadata">

**Author:** [@Carlos\_Magalhaes](https://discuss.elastic.co/u/Carlos_Magalhaes)\
**Replies:** 14\
**Last updated:** [November 29, 2018, 3:15pm UTC](https://discuss.elastic.co/t/logstash-pipeline-configuration-inputs/158288 "2018-11-29T15:15:19Z")

</div>

Hi all, Wanted to check an understanding on multiple pipelines: My understanding of having multiple pipelines is it allows you to have different inputs and outputs for a specific filter and provides better performance …

---

## [Elasticsearch::Transport Cannot get new connection from pool](https://discuss.elastic.co/t/elasticsearch-transport-cannot-get-new-connection-from-pool/34363)

<div class="topic-metadata">

**Author:** [@elain](https://discuss.elastic.co/u/elain)\
**Replies:** 10\
**Last updated:** [December 3, 2015, 7:50am UTC](https://discuss.elastic.co/t/elasticsearch-transport-cannot-get-new-connection-from-pool/34363 "2015-12-03T07:50:41Z")

</div>

Hello everyone I now deployed in the AWS EC2 td-agent, used to collect logs send to elasticsearch, found every about 6 hours, the log can not be normal collection, the newspaper is as follows: 2015-11-11 18:06:37 +08…

---

## [Logstash 5.3 Persistent Queue issue](https://discuss.elastic.co/t/logstash-5-3-persistent-queue-issue/81203)

<div class="topic-metadata">

**Author:** [@devsibwarra](https://discuss.elastic.co/u/devsibwarra)\
**Replies:** 11\
**Last updated:** [April 5, 2017, 3:16pm UTC](https://discuss.elastic.co/t/logstash-5-3-persistent-queue-issue/81203 "2017-04-05T15:16:47Z")

</div>

Versions \* OS: Ubuntu 14.04.5 LTS \* Filebeat 5.3.0 from https://artifacts.elastic.co/packages/5.x/apt/ \* Logstash 1:5.3.0-1 from https://artifacts.elastic.co/packages/5.x/apt/ \* Oracle Java(TM) SE Runtime Environment (bu…

---

## [Scale Logstash indexers for \>200,000 messages per minute?](https://discuss.elastic.co/t/scale-logstash-indexers-for-200-000-messages-per-minute/33878)

<div class="topic-metadata">

**Author:** [@jbiggley](https://discuss.elastic.co/u/jbiggley)\
**Replies:** 16\
**Last updated:** [September 21, 2016, 11:01am UTC](https://discuss.elastic.co/t/scale-logstash-indexers-for-200-000-messages-per-minute/33878 "2016-09-21T11:01:25Z")

</div>

First, that isn't a typo. In fact, I want to be able to scale LS to handle \>500,000 (maybe a million) message per minute once we get out of our POC. Our basic setup is as follows: On-prem LS server + Redis \> x1 AWS L…

---

## [Create new field based on msg filed in logstash](https://discuss.elastic.co/t/create-new-field-based-on-msg-filed-in-logstash/25527)

<div class="topic-metadata">

**Author:** [@abathula](https://discuss.elastic.co/u/abathula)\
**Replies:** 10\
**Last updated:** [July 15, 2015, 1:42pm UTC](https://discuss.elastic.co/t/create-new-field-based-on-msg-filed-in-logstash/25527 "2015-07-15T13:42:51Z")

</div>

Hi All, Here i want to create a new field Invoice\_IID based on msg filed, contains Invoice\_IID value in log line msg filed. "msg" =\> "Finished Creating Parent Invoices for Invoice\_IID: 80000000-41fb-1638-cd42-ffff08…

---

## [How to manage multiple namespaces with a single elastic operator](https://discuss.elastic.co/t/how-to-manage-multiple-namespaces-with-a-single-elastic-operator/250188)

<div class="topic-metadata">

**Author:** [@Vineeth\_varma](https://discuss.elastic.co/u/Vineeth_varma)\
**Replies:** 11\
**Last updated:** [October 5, 2020, 9:12am UTC](https://discuss.elastic.co/t/how-to-manage-multiple-namespaces-with-a-single-elastic-operator/250188 "2020-10-05T09:12:56Z")

</div>

Hi, I have deployed elastic operator from the quickstart documentation. I have deployed elasticsearch, kibana from the same documentation under the namespace(elastic-system) where I have deployed the elastic operator. N…

---

## [Kibana cannot connect to Elasticsearch after enabling SSL/TLS](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201)

<div class="topic-metadata">

**Author:** [@saifat29](https://discuss.elastic.co/u/saifat29)\
**Replies:** 17\
**Last updated:** [August 13, 2019, 9:46am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-elasticsearch-after-enabling-ssl-tls/194201 "2019-08-13T09:46:53Z")

</div>

I am running a two node ES cluster and a single Kibana instance using Docker Swarm, everything worked fine before enabling SSL/TLS on the ES nodes. I am using same certificate without hostname verification for all the …

---

## [Ошибка : Could not index event to Elasticsearch](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/203630)

<div class="topic-metadata">

**Author:** [@beren](https://discuss.elastic.co/u/beren)\
**Replies:** 14\
**Last updated:** [October 21, 2019, 2:13pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/203630 "2019-10-21T14:13:40Z")

</div>

Всем привет. В /etc/logstash/conf.d/postfix.conf http://pastebin.calculate-linux.ru/ru/show/127900 В /etc/logstash/patterns/postfix http://pastebin.calculate-linux.ru/ru/show/127901 Но в логах logstash Could not in…

---

## [Logstash 401 Error](https://discuss.elastic.co/t/logstash-401-error/234029)

<div class="topic-metadata">

**Author:** [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Replies:** 10\
**Last updated:** [May 29, 2020, 2:15am UTC](https://discuss.elastic.co/t/logstash-401-error/234029 "2020-05-29T02:15:40Z")

</div>

Hello, I have followed the steps in the below doc to enable security ; Everything seems to have worked. HOwever, when I start logstash, i get the below error : \[2020-05-24T02:16:15,655\]\[WARN \]\[logstash.outputs.elas…

---

## [Problem of connecting python client with elasticsearch](https://discuss.elastic.co/t/problem-of-connecting-python-client-with-elasticsearch/334437)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 12\
**Last updated:** [May 26, 2023, 2:10pm UTC](https://discuss.elastic.co/t/problem-of-connecting-python-client-with-elasticsearch/334437 "2023-05-26T14:10:12Z")

</div>

I am unable to connect with elastic using python client The code which run with no issue is from elasticsearch import Elasticsearch es = Elasticsearch(\['http://\<your\_ip\_address\>:\<your\_port\>'\]) (I use my ip and port w…

---

## [Logstash Grok New Line Syntax](https://discuss.elastic.co/t/logstash-grok-new-line-syntax/192148)

<div class="topic-metadata">

**Author:** [@userR](https://discuss.elastic.co/u/userR)\
**Replies:** 11\
**Last updated:** [July 25, 2019, 9:11pm UTC](https://discuss.elastic.co/t/logstash-grok-new-line-syntax/192148 "2019-07-25T21:11:29Z")

</div>

Hi, I am attempting to parse log data that are on different lines. When its read through filebeat and sent to logstash, the message contains \\n. Unfortunetly, I am unable to deal with this and am getting an error when I…

---

## [Unable to connect to Elasticsearch. Error: \[mapper\_parsing\_exception\] No handler for type \[flattened\] declared on field \[state\]](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-error-mapper-parsing-exception-no-handler-for-type-flattened-declared-on-field-state/215378)

<div class="topic-metadata">

**Author:** [@o1o1o11o1](https://discuss.elastic.co/u/o1o1o11o1)\
**Replies:** 13\
**Last updated:** [February 7, 2020, 4:18pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-error-mapper-parsing-exception-no-handler-for-type-flattened-declared-on-field-state/215378 "2020-02-07T16:18:53Z")

</div>

After upgrading Elasticsearch and Kibana from 7.1 to 7.5.1 Kibana is unable to start with the following error: Unable to connect to Elasticsearch. Error: \[mapper\_parsing\_exception\] No handler for type \[flattened\] declar…

---

## [Shards Initializing Indefinitely?](https://discuss.elastic.co/t/shards-initializing-indefinitely/101204)

<div class="topic-metadata">

**Author:** [@corona](https://discuss.elastic.co/u/corona)\
**Replies:** 9\
**Last updated:** [September 26, 2017, 2:40pm UTC](https://discuss.elastic.co/t/shards-initializing-indefinitely/101204 "2017-09-26T14:40:32Z")

</div>

Hello, We are currently running version 2.4.0 in our production cluster. After node restarts I've noticed we have around 36 shards which seem to be stuck initializing. We have been having problems with nodes crashing d…

---

## [Logstash and cisco asa v9 netflow](https://discuss.elastic.co/t/logstash-and-cisco-asa-v9-netflow/42027)

<div class="topic-metadata">

**Author:** [@ssi](https://discuss.elastic.co/u/ssi)\
**Replies:** 16\
**Last updated:** [May 10, 2016, 8:57pm UTC](https://discuss.elastic.co/t/logstash-and-cisco-asa-v9-netflow/42027 "2016-05-10T20:57:24Z")

</div>

has anyone got this working, i can see some work has been done on the netflow.yaml file in regards to this I've tried adding the changed to my netflow.yaml but i keep getting this error. no matching template for…

---

## [Indexing many pdf files](https://discuss.elastic.co/t/indexing-many-pdf-files/132517)

<div class="topic-metadata">

**Author:** [@Fish](https://discuss.elastic.co/u/Fish)\
**Replies:** 11\
**Last updated:** [May 19, 2018, 1:23am UTC](https://discuss.elastic.co/t/indexing-many-pdf-files/132517 "2018-05-19T01:23:25Z")

</div>

I want to index many pdf files. I read about ingest attachment plugin. I also researched for examples online. One of them is Ingesting and Exploring Scientific Papers using Elastic Cloud. However, I have not yet found a…

---

## [Raid 0 SSD?](https://discuss.elastic.co/t/raid-0-ssd/46504)

<div class="topic-metadata">

**Author:** [@KlavsKlavsen](https://discuss.elastic.co/u/KlavsKlavsen)\
**Replies:** 18\
**Last updated:** [April 8, 2016, 6:40am UTC](https://discuss.elastic.co/t/raid-0-ssd/46504 "2016-04-08T06:40:42Z")

</div>

I was considering setting up servers, with the data disk being raid 0.. since we have a replica on another server.. I figured that would a good way to save a lot of money (SSD's is by far the most expensive part of a new…

---

## [Writing fields.yml](https://discuss.elastic.co/t/writing-fields-yml/44336)

<div class="topic-metadata">

**Author:** [@rvlander](https://discuss.elastic.co/u/rvlander)\
**Replies:** 11\
**Last updated:** [June 13, 2016, 4:41pm UTC](https://discuss.elastic.co/t/writing-fields-yml/44336 "2016-06-13T16:41:20Z")

</div>

Is there a documentation on how to write fields.yml when writing a new beat? Especially some Elastic types seem to be ignored when generating index template. Also how do you describe arrays? Thanks,

---

## [Logstash stopped processing because of an error: (SystemExit) exit](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit/299338)

<div class="topic-metadata">

**Author:** [@RomanKau](https://discuss.elastic.co/u/RomanKau)\
**Replies:** 12\
**Last updated:** [March 15, 2022, 8:21am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit/299338 "2022-03-15T08:21:20Z")

</div>

Running Windows 10, Logstash 8.1.0, elasticsearch, kibana and filebeat 8.0.0 all on the same machine. I also tried running version 8.0.0 of Logstash but I get the same error. Getting the data from filebeat to kibana wor…

---

## [Index Data Missing from "Discover"](https://discuss.elastic.co/t/index-data-missing-from-discover/59585)

<div class="topic-metadata">

**Author:** [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Replies:** 12\
**Last updated:** [September 2, 2016, 11:07pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585 "2016-09-02T23:07:23Z")

</div>

I am viewing the data of index-2016.09.01 from kibana, which i parsed yesterday evening. I can find this index in Setting. However, when i go to Discover, it is not available. Setting the time to "yesterday" or "the day…

---

## [How to check that my log file data is transfered to elasticsearch 5.5.0](https://discuss.elastic.co/t/how-to-check-that-my-log-file-data-is-transfered-to-elasticsearch-5-5-0/94799)

<div class="topic-metadata">

**Author:** [@vivekpandey564](https://discuss.elastic.co/u/vivekpandey564)\
**Replies:** 11\
**Last updated:** [July 27, 2017, 3:23pm UTC](https://discuss.elastic.co/t/how-to-check-that-my-log-file-data-is-transfered-to-elasticsearch-5-5-0/94799 "2017-07-27T15:23:51Z")

</div>

input { file { add\_field =\> \[ "host", "my-dev-host" \] path =\> "D:\\JHipster\_Demo\\logFile.2017-07-27.log" codec =\> "plain" } } filter { date { match =\> \[ "timestamp" , "YYYY/MM/DD:HH…

---

## [Shard limit hit](https://discuss.elastic.co/t/shard-limit-hit/123606)

<div class="topic-metadata">

**Author:** [@jmgarcia](https://discuss.elastic.co/u/jmgarcia)\
**Replies:** 14\
**Last updated:** [March 14, 2018, 1:40pm UTC](https://discuss.elastic.co/t/shard-limit-hit/123606 "2018-03-14T13:40:27Z")

</div>

Well to get down to it we migraded servers this weekend. My script worked before but now it doesnt. I keep on getting an error that "\[{'error': {'root\_cause': \[{'type': 'illegal\_argument\_exception', 'reason': 'Trying t…

[Previous page](https://discuss.elastic.co/top.md?page=30&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=32&per_page=50&period=all)
